Cross-Site Scripting Vulnerability in Monster Menus by Drupal
CVE-2026-81201

Currently unrated

Key Information:

Vendor

Drupal

Vendor
CVE Published:
2 September 2026

What is CVE-2026-81201?

A vulnerability in Drupal's Monster Menus allows malicious users to execute arbitrary scripts in the browsers of users who view affected pages. This stored XSS instead of server-side validation can lead to unauthorized access, session hijacking, and other security issues. Ensure to update to a patched version of Monster Menus to mitigate potential risks associated with this exploit.

Affected Version(s)

Monster Menus 0.0.0 < 9.5.3

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Dan Wilga (gribnif)
Dan Wilga (gribnif)
Greg Knaddison (greggles)
Juraj Nemec (poker10)
Jess (xjm)
.